RHSA-2026:26257HighCVSS 8.8

Red Hat Security Advisory: Assisted Installer RHEL 8 components for Multicluster Engine for Kubernetes 2.8.8

Published
June 16, 2026
Last Modified
August 14, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2025-58058 — github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory CVE-2026-39883 — github.com/open-telemetry/opentelemetry-go: OpenTelemetry-Go: Arbitrary code execution via PATH hijacking on BSD/Solaris

🎯 Affected products5

  • multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:2c6a0275687920af7a4852828689429b54fc89f5f6d457fc5b00e6300bef47ff_ppc64le as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:78857cf0c460c7639b30bcee92cff7e5e2c8d0423e42522267c4d9ace96ad1b9_s390x as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:96d38a23205177fb651c7eac72711143cdbc847d29d26d60e1b364e3dd969f25_amd64 as a component of multicluster engine for Kubernetes 2.8
  • registry.redhat.io/multicluster-engine/assisted-service-8-rhel8@sha256:aa1b61f73bdfc1b60d1fa100e2b060eca0ef578c69a681f7603b49d81fc273ce_arm64 as a component of multicluster engine for Kubernetes 2.8

✅ Remediation

For more information about Assisted Installer, see the following documentation: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/clusters/cluster_mce_overview#cim-intro For multicluster engine for Kubernetes, see the following documentation for details on how to install the images: https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_management_for_kubernetes/2.13/html/clusters/cluster_mce_overview#mce-install-intro This documentation will be available after the general availability release of Red Hat Advanced Cluster Management 2.13. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)